Blank Grabber
Blank Grabber is an information-stealing trojan/infostealer. The provided content states that it targets passwords, cookies, and autofill data from Chromium-based browsers; steals complete Discord and Telegram sessions; and steals seed phrases/private keys from more than 20 cryptocurrency wallets, with MetaMask, Exodus, and Electrum explicitly named. The content associates Blank Grabber with Lazarus Group / APT-C-26 activity. In the reported campaign, Lazarus distributed a malicious RAR archive, including lures such as "Pharos.rar" / "Pharos-Automation-Bot," exploiting the WinRAR path traversal vulnerability CVE-2025-8088 (described as an ADS path validation flaw enabling arbitrary file creation). Exploitation created a malicious BAT file in the Windows Startup folder for execution and persistence, which then downloaded and executed an obfuscated Python loader that deployed Blank Grabber. The campaign reportedly used Dropbox and Pastebin for payload staging and Telegram for command-and-control and/or exfiltration. The content specifically notes targeting of browser credentials and session data, Telegram/Discord data, and wallet secrets.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
captured a new sample from the Lazarus group that uses the WinRAR vulnerability CVE-2025-8088 for poisoning attacks... downloading a Blank Grabber information-stealing Trojan... targets passwords... and steals seed private keys...
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...subsequently downloading a Blank Grabber information-stealing Trojan. This Trojan primarily targets passwords, cookies, and autofill data in Chromium-based browsers, steals complete Discord and Telegram sessions, and steals seed private keys from over 20 mainstream encrypted wallets..."
Techniques & procedures
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
1 technique
Execution
Credential Access
3 techniques
Credential Access
Collection
1 technique
Collection
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information-stealing malware used to harvest credentials and sensitive data from Chromium-based browsers, messaging platforms (Telegram/Discord), and cryptocurrency wallets (seed phrases/private keys).
Information stealer attributed in the content to Lazarus activity; steals browser credentials/cookies/autofill, Discord/Telegram sessions, and seed/private keys from numerous crypto wallets (e.g., MetaMask, Exodus, Electrum).
Blank Grabber is an infostealer malware deployed by APT-C-26 (Lazarus) in campaigns exploiting WinRAR vulnerabilities.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.